#auth0

17 posts · Last used 15d

Part seven of my apidays workshop demo series. Two new features shipped correctly and the chat model couldn't reach either of them, because a Model Context Protocol server and a chat route keep two separate tool lists in this codebase - updating one doesn't update the other. Also found: every page's browser tab had read "Create Next App" since the very first commit. https://tobytes.com/a/74 #auth0 #mcp #ai
0
0
1
0
A password login and a passkey login are the same verified persona, holding the same role, with a completely different answer to "how strongly did you just prove that." Modelling session assurance and step-up in OpenFGA as a public wildcard plus a condition that stores nothing on the tuple at all - and why the elevated session behind it has to stay genuinely ephemeral for any of it to be honest. https://tobytes.com/articles/session-assurance-step-up-fga #auth0 #fga #identity
0
0
0
0
Building an apidays workshop demo with Claude Code doing the implementation, I had it run an adversarial review of the build plan before either of us wrote application code. It found a structural flaw in the Auth0 FGA model, not a polish problem - the check was always true, so there was nothing for an AI agent to be denied and nothing to delegate. https://tobytes.com/articles/why-the-apidays-workshop-plan-restarted-from-scratch #auth0 #fga #ai #identity
0
1
1
0
Auth0 Anonymous Sessions sets the auth0_anon cookie only on a genuine create call, never on a renewal - confirmed by testing both explicit session_token and cookie-only renewals. Metadata is fixed at creation too, by design. Same underlying reason for both, and it forces a different pattern for tracking anything (a cart, in my case) across the handoff to login. https://tobytes.com/articles/auth0-anonymous-sessions-fixed-at-creation #auth0 #identity #webdev
0
0
0
0
My live Auth0 session and token demo grew three new patterns since I first wrote this up: CIBA against a real Guardian push (now with a Rich Authorization Requests toggle), the Device Authorization Grant, and a comparison against a real Hono app on Cloudflare Workers. The session view also moved out of a single profile page into a sidebar that's visible on every page in the app. https://tobytes.com/articles/auth0-token-session-demo #auth0 #oauth #identity
0
0
0
0
Updated my Auth0 session and token management taxonomy with two grant types I'd left out the first time: CIBA and the Device Authorization Grant. Both are decoupled from the requesting device's own browser but solve different problems. Also added what Rich Authorization Requests (part of Highly Regulated Identity) changes on a CIBA push - structured fields instead of one opaque string. https://tobytes.com/articles/auth0-session-token-management-options-explained #auth0 #oauth #identity
0
0
0
0
Built a live Auth0 demo with eight integration patterns side by side. The interesting part: a unified profile page that correlates Traditional, BFF, and SPA sessions via the session_id field on refresh tokens - showing which apps share an Auth0 AS session and which are isolated. Also covers MRRT exchange ledger, Fingerprint ad-blocker bypass, On-Behalf-Of delegation, and Custom Token Exchange. https://tobytes.com/articles/auth0-token-session-demo #Auth0 #OAuth #Identity
0
0
0
0
OpenID's Shared Signals Framework and Continuous Access Evaluation Profile went final in August 2025. Auth0 has no native role in either direction of the standard. I built a reference implementation anyway - signed SETs out, verified CAEP signals in, a shared policy enforcement point instead of a heavier authorisation service, and CIBA as the backend-initiated step-up mechanism. https://tobytes.com/articles/continuous-access-evaluation-for-auth0-caep-ssf-demo #auth0 #identity #ciba
0
0
0
0
You've seen all posts